Listen to this Post
CVE-2026-64866 is a missing authorization vulnerability identified in QuantumNous New API, an LLM gateway and AI asset management system. The flaw resides in the `AdminResetPasskey` function within controller/passkey.go. This endpoint, exposed via DELETE /api/user/:id/reset_passkey, is designed to allow administrators to reset a user’s passkey authentication factor.
The vulnerability arises because this endpoint lacks the `canManageTargetRole` authorization check. This check is a role-level control used by other privileged account-protection endpoints to ensure that an administrator can only perform sensitive operations on users with equal or lower privileges. In affected versions (from v0.9.1.3 up to, but not including, v1.0.0-rc.7), this control is missing.
Consequently, a lower-privileged administrator can send a crafted `DELETE` request to this endpoint targeting a same-level or higher-privileged user, including root-level accounts. If the target has a passkey configured, the attacker can remove this authentication factor, weakening the account’s security boundary. While the attacker still requires administrator privileges, making the issue’s severity Medium, it represents a significant bypass of intended access controls. The flaw is classified under CWE-862: Missing Authorization. The fix, implemented in version v1.0.0-rc.7, adds the missing `canManageTargetRole` check before any passkey lookup or deletion occurs.
DailyCVE Form:
Platform: QuantumNous New API
Version: 0.9.1.3–1.0.0-rc.6
Vulnerability: Missing Authorization
Severity: Medium
Date: 2026-08-17
Prediction: 2026-08-24
What Undercode Say:
Analytics:
The vulnerability exists in the `AdminResetPasskey` function. The following command can be used to check if a system is running a vulnerable version:
Check the version of New API ./new-api --version Or check the version in the source code grep -r "Version" .
To verify if the endpoint is accessible, an administrator can use curl:
Attempt to reset a passkey for a target user (requires admin session) curl -X DELETE "https://target-instance.com/api/user/123/reset_passkey" \ -H "Authorization: Bearer <admin_token>"
The `canManageTargetRole` check is implemented in controller/passkey.go. The relevant code path before the fix would lack this check:
// Vulnerable code path (before v1.0.0-rc.7)
func AdminResetPasskey(c gin.Context) {
userID := c.Param("id")
// Missing: canManageTargetRole check
// Proceeds to delete passkey for userID
}
The fix adds the missing authorization check:
// Patched code path (v1.0.0-rc.7 and later)
func AdminResetPasskey(c gin.Context) {
userID := c.Param("id")
if !canManageTargetRole(c, userID) {
c.JSON(403, gin.H{"error": "Forbidden"})
return
}
// Proceeds to delete passkey for userID
}
Exploit: (Educational Purposes!)
An attacker with lower-privileged administrator access can exploit this by:
1. Identifying a Target: Determine the user ID of a same-level or higher-privileged account (e.g., a root account).
2. Crafting the Request: Send a `DELETE` request to the vulnerable endpoint: DELETE /api/user/<target_id>/reset_passkey.
3. Executing the Attack: Include a valid session token for the lower-privileged administrator in the request headers.
4. Outcome: If successful, the target user’s passkey is removed, weakening their account security and potentially leading to account lockout or facilitating further attacks.
Example exploit using curl curl -X DELETE "https://target-instance.com/api/user/2/reset_passkey" \ -H "Authorization: Bearer <low_privilege_admin_token>"
Protection:
Immediate Upgrade: The primary fix is to upgrade to v1.0.0-rc.7 or later. This version includes the `canManageTargetRole` check in the `AdminResetPasskey` function.
Temporary Workarounds:
Restrict Endpoint Access: Use a reverse proxy or firewall to block the `DELETE /api/user/:id/reset_passkey` endpoint for all but trusted root operators. Example Nginx configuration:
location ~ ^/api/user/./reset_passkey$ {
deny all;
}
Implement Custom Middleware: If an immediate upgrade is not possible, apply a temporary patch to add the missing `canManageTargetRole` authorization check in the `AdminResetPasskey` function.
Limit Admin Access: Restrict administrator access to only trusted operators and limit the number of admin accounts.
Impact:
Account Security Weakening: A lower-privileged administrator can remove the passkey (a strong authentication factor) from same-level or higher-privileged accounts, including root.
Denial of Service: In multi-tenant environments, this could disrupt operations by locking out other administrators, requiring manual intervention to restore access.
Privilege Escalation Potential: While the attacker needs admin privileges, combining this with other vulnerabilities could enable further account takeover.
CVSS Score: The issue has a CVSS v4.0 base score of 5.1 (Medium), with a vector of CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

